Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Why does loopback mode trump GPPE drive maps but not GPO user logon script?

Posted on 2013-06-17
1
Medium Priority
?
1,156 Views
Last Modified: 2013-06-18
I recently migrated my users to a new GPO structure, taking advantage of numerous Group Policy Preferences. I’ve stumbled on to an issue where users’ drive mappings are not being made when they log into a conference room computer.

These conference room computers have loopback enabled (“Replace”) so I can lock several, albeit minor, settings down. The drive mappings are done via User GPPE > Windows Settings > Drive Maps. In the old days, I did it with a GPO user logon script (which worked). The GPPE drive maps do not work.

If I change the loopback mode to “merge”, it will work, but then I lose my ability to lock stuff down.

Anyone have an explanation or advice how to get around this?
0
Comment
Question by:RhoSysAdmin
1 Comment
 
LVL 85

Accepted Solution

by:
oBdA earned 2000 total points
ID: 39255324
To start with: you don't lose the ability to "lock stuff down" with Loopback processing in Merge mode.
All that Loopback mode does is tell the OS to apply user configuration GPOs based on the OU where the computer account is.
In "Merge" mode, the user configuration GPOs will be applied based on the user object's location in AD first, then the user configuration GPOs based on the computer object's location in AD (so that with concurrent policies, the one applied via Loopback will always win).
In "Replace" mode, any user configuration GPO based on the user object's location in AD will be skipped altogether, and only the ones linked to the computer object's location will be applied.
So you can either use "Merge" mode, making use of the Loopback's higher priority to lock down whatever was allowed in the default GPOs, or you can use "Replace" mode to log the users on with a clean slate, put all the drive mapping GPPs into their own dedicated GPO, and link the drive mapping GPO not only to the user OU, but to the conference room OU as well (or duplicate the GPPs, but if you need the same drive mappings, then that's not really the best solution).
Loopback processing of Group Policy
http://support.microsoft.com/kb/231287
0

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Suggested Courses

963 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question